Skip to content
Program Podz

Privacy Policy

Program Podz — controller/business: MoonLeague LLC, A Florida Limited Liability Company, based in Polk County, Florida. Effective: [INSERT DATE] · Last updated: [INSERT DATE].

⚠️ Placeholder draft for attorney review — not yet legal advice. Written to adapt to U.S. state laws (including California CCPA/CPRA) and, if you serve users abroad, EU/UK GDPR. Items in [BRACKETS] are decisions your attorney should confirm.

📌 Plain-English summary: We collect what we need to run Program Podz for you — your account info, the projects and activity you create, payment status (not full card numbers), and basic device/usage data. Your connected AI keys are stored access-restricted and server-side and are not shown back to you in full. We do not sell your personal information. We use trusted service providers (hosting, payment, and AI providers) to operate the Service. You have choices and rights over your data, described below. If this summary conflicts with the detailed policy, the detailed policy controls.

1. Scope

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use the Service, visit our sites, or communicate with us. When you build and deploy a project that collects personal data from your own end users, you are the controller/business for that data; this policy covers our processing of information about you (our user) and, where applicable, our processing of your end-user data on your behalf as a service provider/processor [confirm processor role and whether a DPA is offered]. This policy does not cover third-party services you connect, which have their own privacy policies.

2. Information we collect

Information you provide: account information (name if provided, email, username, password stored hashed, profile details); billing information (subscription/plan status and billing records — card payments are processed by our payment processor and we do not store full card numbers); Your Content (projects, prompts, instructions, code, text, files); connected-service credentials (API keys and tokens you choose to connect, stored access-restricted and server-side); and communications you send us.

Information collected automatically: usage data (features used, build activity, meter estimates, timestamps, logs); device and connection data (IP address, browser type, operating system, similar identifiers); and cookies and similar technologies for authentication, security, preferences, and (if applicable) analytics [confirm cookie inventory and whether a consent banner is required].

Information from third parties: payment status and limited billing metadata from our processor, and limited data returned by services you connect [confirm any other sources].

AI processing: when you use AI features, your prompts, instructions, and relevant project context are transmitted to the AI provider(s) you use or that we make available so they can generate output; those providers process that data under their own terms [confirm providers and their retention/training defaults]. We do not seek to collect sensitive personal information to operate core features — please do not put sensitive information into prompts unless necessary and lawful. The Service is not directed to children under [13 / 16 — confirm], and we do not knowingly collect their personal information.

3. How we use information

We use personal information to: (a) provide, operate, and maintain the Service, including running your builds and showing your usage meter; (b) authenticate you, secure the Service, prevent fraud and abuse, and enforce our Terms; (c) process payments and manage subscriptions, Launch Passes, Care Plans, and Playbook transactions; (d) provide support; (e) improve and develop the Service, including troubleshooting and analytics [state clearly if you do NOT use private project content to train models]; (f) send administrative and transactional messages and, with consent where required, product updates; and (g) comply with legal obligations and enforce our rights. Where GDPR applies, our legal bases are performance of a contract, legitimate interests, consent, and legal obligations [confirm applicability].

4. How we disclose information

We do not sell your personal information [confirm no "sharing" for cross-context behavioral advertising under CPRA]. We disclose information only to: service providers/processors (hosting, storage, payment processing, email, support, security, analytics) under contract; AI providers (to generate output when you use AI features); connected services you choose (hosts and platforms you deploy to or integrate with, at your direction); other users or the public (content you choose to publish, share, or sell, such as deployed projects and Playbooks); legal and safety recipients (to comply with law or lawful requests and to protect rights, property, or safety); a successor in a merger, acquisition, financing, or asset sale, subject to this policy; and others with your consent.

5. Retention

We retain personal information for as long as your account is active and as needed to provide the Service, then for a reasonable period afterward to comply with legal, tax, accounting, and security obligations, resolve disputes, and enforce agreements. Specific windows may apply to certain data (for example, artifacts, logs, and Care-related backups) [insert specific periods]. On account termination, we make Your Content available for export for [NUMBER] days where feasible, after which it may be deleted; backups may persist for a limited additional period [confirm — must match the Terms].

6. Security

We use reasonable technical and organizational measures designed to protect personal information, including access-restricted, server-side storage for connected-service keys and secrets, which are not displayed back to you in full and are not stored in source control [confirm measures are accurately described — e.g., encryption at rest/in transit, access controls, logging]. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a data breach affecting your personal information occurs, we will notify you and authorities as required by applicable law [confirm breach-notification procedures and timelines].

7. Your rights and choices

All users: you can access and update account information, disconnect connected services, delete projects, and contact us with privacy requests. U.S. state privacy rights (e.g., California CCPA/CPRA and similar laws): depending on your state, you may have rights to know/access, delete, correct, opt out of "sale"/"sharing" and certain profiling, and not be discriminated against for exercising rights — we do not sell personal information [confirm state coverage and add required disclosures if thresholds are met]. EU/UK (GDPR), if applicable: you may have rights to access, rectify, erase, restrict or object to processing, data portability, and to withdraw consent, and to lodge a complaint with a supervisory authority [confirm applicability, EU/UK representative, and transfer mechanism]. To exercise rights, contact us through the channels below; we will verify your identity and respond within the time required by law. You can opt out of marketing emails via the unsubscribe link; transactional messages will still be sent.

8. International data transfers

We are based in the United States and process information there and potentially in other countries where our providers operate. If you access the Service from outside the U.S., your information may be transferred to and processed in the U.S. and elsewhere. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for cross-border transfers [confirm if serving EU/UK users].

9. Cookies and similar technologies

We use cookies and similar technologies for authentication, security, remembering preferences, and (if applicable) analytics and performance. You can control cookies through your browser settings; disabling some may affect functionality [insert cookie inventory; determine whether a consent banner is required]. [State how you respond to browser "Do Not Track" / Global Privacy Control signals — CPRA requires honoring recognized opt-out preference signals.]

10. Third-party services and links

The Service integrates with and links to third-party services (AI providers, code hosts, cloud/hosting platforms, payment processors). Their processing is governed by their own privacy policies, which we encourage you to review. We are not responsible for their practices.

11. Automated processing and AI

The Service uses AI models to generate output at your direction. This is not automated decision-making that produces legal or similarly significant effects about you [confirm — if any automated decisioning with significant effects exists, add GDPR Art. 22 disclosures and safeguards]. AI output may be inaccurate; do not rely on it without your own review.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (for example, by posting the updated policy with a new "Last updated" date and/or notifying you). Your continued use after changes take effect constitutes acceptance where permitted by law.

13. Contact

Questions or privacy requests? Reach us through the Contact page. The Service is provided by MoonLeague LLC, A Florida Limited Liability Company, based in Polk County, Florida. [If GDPR applies, add EU/UK representative and Data Protection Officer contact if required.]